The tech companies will just use face recognition, tracing, gait recognition, unique properties (like scratches) etc. etc. for the same purpose, same way they pioneered browser fingerprinting.
For a random blog you have never visited before and have no reason to trust. It could attempt to do all the malicious things that you are worried a man in the middle would do.
The browser still has to execute code over HTTPS. You've just moved the injection perimeter from inside my own network into the providers website. I don't think you've fundamentally changed your level of risk unless you spend a huge amount of time browsing on shared password WPA protected wifi networks.
You cannot browse to sites under any regime and execute code while expecting security to exist.
A few of them also have locked in power agreements.
Almost none of them have the expertise to build anything. Some of them are even outsourcing that to geezer tech and consulting shops.
It's not going to go well.
reply